Why Payment Fraud Is Becoming Harder to Detect

One major incident involved a fraudster compromising a client’s vendor workflow and convincing the company to change payment details, resulting in a loss of more than one million dollars. The experience demonstrated how traditional security controls can struggle against fraud that appears legitimate.

Shai notes that many organizations still rely on traditional bank account validation, even though attackers increasingly use legitimate banking infrastructure. Fraudsters can compromise vendors, understand approval processes, and use valid credentials, making their activity difficult to distinguish from normal business operations.

FinTech Interview with Shai Gabay

New ACH Rules Raise the Bar

The ACH Network processes trillions of dollars in payments each year, but payment fraud continues to evolve. Fraudsters increasingly combine identity manipulation, social engineering, and legitimate financial information to make fraudulent payment requests appear genuine.

Nacha’s changes addressing payments made through deception, including “false pretenses,” are designed to strengthen defenses against this type of fraud. Organizations will need stronger controls, behavioral monitoring, risk-based decision-making, and ongoing reviews rather than relying solely on account validation.

Breaking Down Security Silos

Another challenge is that payment processes often involve multiple departments. Procurement may manage vendors, finance handles payments, IT manages systems, and security monitors threats. When these teams operate independently, important warning signs can be missed.

Email-based attacks demonstrate this problem. IT may identify suspicious activity, while finance sees what appears to be a legitimate vendor request. Without a shared view of payment risk, fraud can easily pass through the gaps.


Comments

Leave a comment

Design a site like this with WordPress.com
Get started